agledger-api a818cc31 (on main, unreleased) adds a disputes:write scope. Opening a dispute, submitting dispute evidence, withdrawing and resolving (POST /v1/records/{id}/dispute, .../dispute/evidence, .../dispute/withdraw, POST /v1/disputes/{id}/resolve, and the A2A open_dispute intent) now require it; disputes:read only reads.
The Server's agent-full and admin-standard profiles now carry disputes:write; admin-observer, agent-readonly, agent-performer-only, admin-iac and admin-schema do not. GET /v1/scope-profiles on the new release is the authority.
What this package needs:
- Add
DISPUTES_WRITE = 'disputes:write' to the scope constants.
- Add it to the
agent-full and admin-standard mirrors. A key minted from a stale mirror 403s on every dispute mutation, and an admin key minted from the stale admin-standard list cannot mint an agent-full key (scope escalation).
- Any dispute helper docs that say
disputes:read gates the mutations are now wrong.
No state left in any other tree.
agledger-api a818cc31 (on main, unreleased) adds a
disputes:writescope. Opening a dispute, submitting dispute evidence, withdrawing and resolving (POST /v1/records/{id}/dispute,.../dispute/evidence,.../dispute/withdraw,POST /v1/disputes/{id}/resolve, and the A2Aopen_disputeintent) now require it;disputes:readonly reads.The Server's
agent-fullandadmin-standardprofiles now carrydisputes:write;admin-observer,agent-readonly,agent-performer-only,admin-iacandadmin-schemado not.GET /v1/scope-profileson the new release is the authority.What this package needs:
DISPUTES_WRITE = 'disputes:write'to the scope constants.agent-fullandadmin-standardmirrors. A key minted from a stale mirror 403s on every dispute mutation, and an admin key minted from the stale admin-standard list cannot mint an agent-full key (scope escalation).disputes:readgates the mutations are now wrong.No state left in any other tree.